Cross-Site Scripting Vulnerability in Landing Pages and Domain Aliases for WordPress
CVE-2025-46533

5.9MEDIUM

What is CVE-2025-46533?

A vulnerability has been identified in the Landing Pages and Domain Aliases plugin for WordPress, allowing for the improper neutralization of input during web page generation. This results in a Stored Cross-Site Scripting (XSS) issue, enabling attackers to inject malicious scripts through user input. Affected versions include anything below 0.8. It is crucial for site administrators to patch their installations to prevent unauthorized code execution and protect user data.

Affected Version(s)

Landing pages and Domain aliases for WordPress <= 0.8

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan (Patchstack Alliance)
.